[German]Mozilla developers have released version 90.0.0 and 78.12.0 ESR of the Firefox browser on July 13, 2021. The version 90.0.0 is a new development branch of the browser, and the ESR is a security update, which should eliminate vulnerabilities, but also fix bugs.
According to the release notes, version 90.0.0 brings some new features as well as bug fixes and security fixes. Here is a rough overview of the new features:
- On Windows, updates can now be applied in the background while Firefox is not running.
- Firefox for Windows now features a new about:third-party page to identify compatibility issues caused by third-party applications
- Exceptions to HTTPS-only mode can be managed in about:preferences#privacy
- Printing to PDF now creates working hyperlinks
Furthermore, there is version 2 of Firefox’s SmartBlock feature, which further improves private browsing. Third-party Facebook scripts are blocked to prevent you from being tracked. However, the scripts are now automatically loaded “just in time” when you choose to “Sign in with Facebook” on a website.
In addition, some security vulnerabilities that are rated as high or moderate have been fixed in the new version.
- CVE-2021-29970: Use-after-free in accessibility features of a document
- CVE-2021-29971: Granted permissions only compared host; omitting scheme and port on Android
- CVE-2021-30547: Out of bounds write in ANGLE
- CVE-2021-29972: Use of out-of-date library included use-after-free vulnerability
- CVE-2021-29973: Password autofill on HTTP websites was enabled without user interaction on Android
- CVE-2021-29974: HSTS errors could be overridden when network partitioning was enabled
- CVE-2021-29975: Text message could be overlaid on top of another website
- CVE-2021-29976: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12
- CVE-2021-29977: Memory safety bugs fixed in Firefox 90
Details may be found within the links sections of the Firefox page.
Firefox 78.12.0 esr
An update of Firefox 78.12.0 esr with one year of long-term support with the same fixed vulnerabilities has also been provided. The new Firefox and the ESR variant can be downloaded from this website for various platforms (the variant is to be selected via the list boxes displayed).
Cookies helps to fund this blog: Cookie settings